Skip to main content
Breach Signal

Breach report

Food & Restaurants

Panera Bread

Panerabread.com Leaks Millions of Customer Records

A flaw on Panera Bread's website left millions of customer records open to anyone who knew where to look, and the bakery-cafe chain took eight months to act after a researcher reported it, a delay that became the story's focal point.

Reported by Krebs on Security

Records exposed

37M

Up to 37 million customer records (Panera disputed)

Scale vs. largest on file

When
2017–2018 (disclosed 2018)
How they got in
Unauthenticated API endpoint with sequential customer IDs
Sector
Food & Restaurants

On April 2, 2018, security journalist Brian Krebs reported that Panera Bread's website had been exposing customer records in plain text to anyone who queried it. The data covered people who had signed up for accounts to order food online or join the MyPanera loyalty program, and included names, email addresses, physical addresses, birthdates and the last four digits of payment card numbers. Krebs initially estimated the exposure at more than 7 million records and later reported that the total, including other parts of Panera's systems, might exceed 37 million.

The problem stemmed from an application programming interface that returned customer information without requiring authentication. Because account identifiers were assigned sequentially, anyone could automate requests and walk through the entire customer database. Records could also be searched by phone number, email address or loyalty card number, making it easy to pull details on specific people.

What made the incident notable was the timeline. Security researcher Dylan Houlihan had reported the flaw to Panera in August 2017. According to Houlihan, the company's security director initially dismissed his report as a possible scam and later said the issue was being handled, yet the data remained accessible for roughly eight months. Only after Krebs contacted Panera did the company take the site offline for fixes. Panera then said it had resolved the problem and that fewer than 10,000 customers were likely affected, a figure that security researchers disputed given how easily the data could be scraped.

Panera said it had found no evidence that payment card information or large numbers of records had been accessed. The company did not face major regulatory penalties, but the episode drew widespread criticism from the security community and consumer advocates, and a class action lawsuit followed. It also raised questions about how companies handle vulnerability reports from outside researchers, particularly those without a formal disclosure program.

The Panera leak is frequently cited as an example of broken object-level authorization, one of the most common and dangerous API security flaws. It showed that data does not need to be stolen by sophisticated attackers to be exposed at scale; a simple coding oversight can be enough. For businesses, the lesson was to authenticate every API request, avoid predictable identifiers and treat good-faith researcher reports as urgent. For consumers, it was a reminder that loyalty programs collect more personal information than many people realize.

More from the wire

More in Food & Restaurants.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.